Courseiva
mediumMultiple Choice

CRISC Practice Question: During a review of third-party vendor risks, the…

During a review of third-party vendor risks, the risk team identifies that a cloud service provider's data center is located in a country with unstable political conditions. What should the risk practitioner do FIRST?

⚠ Common exam trap

The trap here is that candidates may jump to a risk treatment action (accept, mitigate, or terminate) without first completing the foundational step of documenting and assessing the risk.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Document the risk and assess its potential impact.

The risk practitioner's first step should be to document the identified risk and assess its potential impact on the organization. This aligns with the CRISC framework's emphasis on risk identification and assessment before any treatment decisions are made. Without a thorough impact assessment, the organization cannot determine whether the risk is acceptable, requires mitigation, or warrants contract termination.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Document the risk and assess its potential impact.

    Why this is correct

    Risk identification precedes evaluation, so the practitioner must first record the geopolitical threat in the risk register, then assess likelihood and impact against the cloud provider's data centre location before recommending any treatment or transfer.

  • ✗

    Accept the risk based on the vendor's SLA.

    Why it's wrong here

    Acceptance requires documented risk evaluation and authorisation, which has not occurred; an SLA cannot transfer geopolitical exposure. It is tempting as a valid response once risk is assessed and within tolerance, and would be correct after analysis shows the residual risk is acceptable to management.

  • ✗

    Request the vendor to move data to another region.

    Why it's wrong here

    Requesting relocation presumes a response before the risk is analysed and may not be feasible or contractual. It is tempting because it directly removes the geographic exposure, and would be correct as a mitigation once assessment confirms the risk exceeds tolerance and the vendor can contractually relocate.

  • ✗

    Terminate the contract immediately.

    Why it's wrong here

    Terminating the contract immediately is a drastic response that ignores due diligence; the practitioner should first assess the risk's likelihood and impact and evaluate mitigations or alternatives. It is tempting because contract termination is a valid risk treatment, but only after assessment shows the risk exceeds tolerance and other options are exhausted.

About these practice questions

One of 1,062 original CRISC practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CRISC practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CRISC exam.